❌

Normal view

The Skills That Will Matter for Offensive AI Security in 2026

13 February 2026 at 14:00

Before tools, before frameworks, before hype, offensive security has always been about one thing: Thinking like an attacker. That foundation now defines the offensive AI security skills practitioners will need as AI reshapes the attack surface. AI systems introduce new behaviors and new failure modes, but the core mindset remains the same: understand how a

The post The Skills That Will Matter for Offensive AI Security in 2026 appeared first on OffSec.

Thinking Like an Attacker: How Attackers Target AI Systems

14 January 2026 at 15:04

In September 2025, security researchers at Anthropic uncovered something unprecedented: an AI-orchestrated espionage campaign where attackers used Claude to perform 80–90% of a sophisticated hacking operation. The AI handled everything from reconnaissance to payload development, demonstrating that artificial intelligence has fundamentally changed the threat landscape, not just as a tool for defenders, but as both

The post Thinking Like an Attacker: How Attackers Target AI Systems appeared first on OffSec.

Closing Out 2025 with Gratitude (and Momentum)

19 December 2025 at 12:21

To the OffSec community, As 2025 comes to a close, we want to pause and say thank you. Whether you trained with us, earned a certification, hired through our platform, or cheered others on from the sidelines, you helped make this year one of our most meaningful yet. This year, we focused on one goal:

The post Closing Out 2025 with Gratitude (and Momentum) appeared first on OffSec.

How Will AI Affect Cybersecurity?

9 December 2025 at 14:36

As organizations deploy AI tools to improve detection accuracy, streamline investigations, and strengthen defenses, threat actors are leveraging the same technologies to develop more efficient and adaptive attack methods.Β  This article outlines the current and emerging roles of AI in cybersecurity, including its defensive applications, its misuse by attackers, and the new attack surfaces it

The post How Will AI Affect Cybersecurity? appeared first on OffSec.

How to Gain Experience in Cybersecurity

9 December 2025 at 14:32

Developing meaningful experience in the cybersecurity field is a common challenge for professionals who have already entered the industry and want to advance their cybersecurity skills.Β  As roles become more technical and responsibilities broaden, it becomes clear that foundational exposure alone is not enough. Employers expect practitioners to demonstrate practical capability, sound judgment, and the

The post How to Gain Experience in Cybersecurity appeared first on OffSec.

CVE-2025-55182 – React Server Components RCE via Flight Payload Deserialization

5 December 2025 at 18:34

React Server Components promise less client-side JavaScript, but that convenience can hide serious risk. Learn how CVE-2025-55182 (CVSS 10.0) enables critical RCE in the RSC ecosystem, why it happened, and how the public exploit works against React’s server-side handling.

The post CVE-2025-55182 – React Server Components RCE via Flight Payload Deserialization appeared first on OffSec.

Unauthenticated Remote Code Execution Vulnerability in WSUS Service

3 November 2025 at 17:50

CVE-2025-59287 exposes a critical WSUS deserialization flaw enabling unauthenticated remote code execution via unsafe AuthorizationCookie handling. Learn the risks and fixes.

The post Unauthenticated Remote Code Execution Vulnerability in WSUS Service appeared first on OffSec.

From Failure to 100: How Akas Earned His OSCP+

24 October 2025 at 13:08

In this guide, we’re sharing an inspiring story from one of our OSCP+ Certified Holders who embodies the journey of Try Harder. We’d like to introduce you to Akas Wisnu Aji (justakazh), a Cyber Security Consultant from Indonesia, who became certified in May 2025 after overcoming two failed attempts. Instead of giving up, Akas chose

The post From Failure to 100: How Akas Earned His OSCP+ appeared first on OffSec.

Recent Vulnerabilities in Redis Server’s Lua Scripting Engine

20 October 2025 at 16:21

Discover multiple Redis CVEs, including the critical CVE-2025-49844 β€” a 13-year-old use-after-free vulnerability in the Lua parser that can allow remote code execution and server crashes.

The post Recent Vulnerabilities in Redis Server’s Lua Scripting Engine appeared first on OffSec.

The Complete Guide to Preparing for Your First OffSec Certification

14 October 2025 at 12:34

Prepare for your first OffSec certification with our comprehensive guide. Learn exam structure, costs, technical requirements, and proven study strategies.

The post The Complete Guide to Preparing for Your First OffSec Certification appeared first on OffSec.

❌